2017-09-12 07:16:37

by Mira Ressel

[permalink] [raw]
Subject: [refpolicy] [PATCH] portage: Remove nonsensical dontaudit of an allowed permission

---
portage.te | 1 -
1 file changed, 1 deletion(-)

diff --git a/portage.te b/portage.te
index 5e69d4c..79f2e3e 100644
--- a/portage.te
+++ b/portage.te
@@ -170,7 +170,6 @@ rsync_entry_domtrans(portage_t, portage_fetch_t)
allow portage_fetch_t portage_t:fd use;
allow portage_fetch_t portage_t:fifo_file rw_fifo_file_perms;
allow portage_fetch_t portage_t:process sigchld;
-dontaudit portage_fetch_t portage_devpts_t:chr_file { read write };

# transition to sandbox for compiling
spec_domtrans_pattern(portage_t, portage_exec_t, portage_sandbox_t)
--
2.14.1


2017-09-12 23:07:18

by Chris PeBenito

[permalink] [raw]
Subject: [refpolicy] [PATCH] portage: Remove nonsensical dontaudit of an allowed permission

On 09/12/2017 03:16 AM, Luis Ressel via refpolicy wrote:
> ---
> portage.te | 1 -
> 1 file changed, 1 deletion(-)
>
> diff --git a/portage.te b/portage.te
> index 5e69d4c..79f2e3e 100644
> --- a/portage.te
> +++ b/portage.te
> @@ -170,7 +170,6 @@ rsync_entry_domtrans(portage_t, portage_fetch_t)
> allow portage_fetch_t portage_t:fd use;
> allow portage_fetch_t portage_t:fifo_file rw_fifo_file_perms;
> allow portage_fetch_t portage_t:process sigchld;
> -dontaudit portage_fetch_t portage_devpts_t:chr_file { read write };
>
> # transition to sandbox for compiling
> spec_domtrans_pattern(portage_t, portage_exec_t, portage_sandbox_t)

Merged.

--
Chris PeBenito